Privacy Policy
Last updated: September 19, 2026
In short
Sheva helps you set a weekly budget, record expenses, and see how much remains. This policy applies to the Sheva website and the Sheva apps for Android and iOS, and explains what information is stored, why it is used, and how you can delete it.
Information we store
Your device may store budgets, expenses and planned expenses, amounts, dates, categories, merchant names and notes; no-spend days; a stated age used to check eligibility; and preferences such as display name, language, currency, week start, goals, character, and hat. With a connected account, profile and budget data may sync to the cloud. Sheva does not currently connect to your bank account or ask for bank passwords or credentials.
Budget and savings calculator
If you use the calculator, your income, entered planning details and interim results are stored locally on your device so you can continue the calculation and edit them again from Profile. They are not sent to analytics providers or stored in the cloud. Only if you confirm a budget update will the selected weekly amount be saved as part of your Sheva budget and synced if you have connected an account.
Accounts and sign-in
You may use Sheva as a guest. In guest mode, budget data stays on your device and no cloud account is created for you. Depending on the device and app version, sign-in options may include Google, Apple, or email. If you register or sign in, we store a user identifier and basic sign-in details the provider supplies, such as an email address, and can sync your Sheva data to the account and send reports you request to that address. The sign-in provider does not receive your Sheva spending history.
Shared budgets
Where sharing is available and you opt in, two separately registered and verified accounts manage a separate budget by agreement. Both see shared display names, the budget, expenses, notes and plans; personal history is not copied. Invitations send the recipient address, inviter name and a time-limited link to Resend, without expense details. Either member can export a shared report to their own email. Leaving or deleting an account ends access and retains a read-only archive for the remaining member, without linking records to the departed account. Free-text notes or descriptions may still identify someone. A new partner cannot join the archive, which is deleted when the final member leaves. Shared writes require internet; an unconfirmed write may temporarily be kept in secure device storage for retry.
Website and enquiries
When you visit the website, the hosting or site-building provider may process basic technical information such as IP address, device type, and security logs. If you contact us through a form or email, we process your contact details and message to respond and handle the request. Analytics tools or non-essential cookies will be used only in line with the notice and choices shown on the website, if enabled.
How we use information
We use information to operate budgets and history, calculate summaries, sync and restore data when you connect an account, create and send a spreadsheet report only when you request one, secure accounts, and troubleshoot issues. Infrastructure providers may process basic technical information, such as IP addresses and request logs, for security, abuse prevention, and reliability. We do not sell personal information or use your expenses for targeted advertising.
Product improvement data — opt-in only
Only with explicit consent, we send limited interaction events, final onboarding answers, and minimized weekly outcome indicators derived from budget data to PostHog and Supabase: budget-use range, whether you stayed within budget, and counts of expenses or no-spend days. They exclude exact budget, expense and balance amounts, merchants, notes, name, email, and advertising identifiers. Events use a random installation identifier and may be linked to the account identifier after sign-in, so they are pseudonymous rather than anonymous. Declining does not affect app features. Withdrawal stops new collection, clears local queues and the Supabase copy, and starts scheduled erasure at PostHog.
Where information is stored
Information is stored on your device. Only after you register or sign in is account and budget information also stored with Supabase for sync and recovery. Information may be processed in other countries under the service provider’s safeguards.
Sharing with third parties
We share information only with providers needed to operate the service, such as Supabase, PostHog, and the sign-in provider you select, or when required by law. If you request an email report, your email address and report, including the expense details you choose to export, are sent to Resend, our email provider, for delivery. We do not share your spending history with advertisers.
Retention and deletion
Local information is kept until app data or the account is deleted. Cloud account and budget data is kept while the account is active. Product-improvement events are kept for up to 12 months; consent-choice records are kept until account deletion or as legally required. Resend may retain message data and logs for up to 30 days and backups for up to 7 additional days. Identifiers needed to complete erasure are retained only until completion, and a target-free operational receipt is deleted after 90 days. Temporary backups and legal duties may delay final deletion.
Completing deletion at providers
Account deletion removes the identity, sessions and active personal-budget data. Shared archives follow the rules above. PostHog event deletion runs on a schedule and is checked against provider status. Resend has no per-message deletion API, so the request remains tracked through its documented 30-day retention period plus a one-day safety margin. Provider identifiers and status are kept temporarily only to run this process. Recipient mailbox copies are outside Sheva’s control.
Your choices
You can update certain details in the app, choose whether to connect a recoverable account, choose whether to request an email report, separately choose whether to share product improvement data, withdraw consent and erase optional interaction events, and request access, correction, or deletion through the support channel.
What happens if you decline
You can use Sheva as a guest without an account; this means no cloud sync, cross-device recovery, email reports, or shared budget. You can decline analytics without losing any product feature. Email is required only for email-based accounts or a report you request. Shared budgeting starts only after explicit opt-in, and declining leaves personal use unchanged.
Security
We protect information using encrypted network communication, secure on-device storage for sign-in tokens, and database controls that restrict each user to their own data. We limit permissions and access to what is necessary. No system is completely secure, so absolute security cannot be guaranteed.
Age requirement and teen privacy
Sheva is intended for users aged 13 and over. Users aged 13–17 may use the service only after a parent or legal guardian has read and approved the Terms of Use and Privacy Policy. Product-improvement analytics remain disabled for minors. We do not knowingly request personal information from anyone under 13. If you learn that a user under 13 submitted information to us, contact support so we can review and delete it as appropriate. A parent or legal guardian may contact us on behalf of a minor user about access, correction, or deletion.
Policy changes
We will update the policy date when material changes are made and provide an appropriate in-app notice when required.
Contact
Sheva is operated by Lusil Blekherman. For privacy requests, account deletion, or legal questions, contact us at sheva.app.support@gmail.com.